Privacy Policy

What we collect, why, who it goes to, and what you can do about it.

Effective 2026-08-06

This is a translation provided for convenience. The Chinese version of this document governs; where the two differ, the Chinese text controls.

1. General

This policy describes how the company handles your information when providing the HERO hosted service.

One thing first: self-hosted and hosted are different paths with different data boundaries. When you deploy HERO yourself, sessions, transcripts, and CLI processes stay on your machine and never reach us, and almost none of this policy applies. This policy is about the hosted control-plane instances we operate.

2. What we collect

Account information: email address, a password hash, and any company name or contact details you choose to provide.

Transaction information: order number, plan, amount, the transaction ID and payment status returned by the payment channel, and invoicing details. We never see or store your card number or payment password — those are handled by Alipay and WeChat Pay.

Service operation information: your instance domain, provisioning and expiry dates, node count and liveness, and control-plane user count.

Logs: IP address, timestamp, user agent, and request path for visits to this site and the console, used for security auditing and troubleshooting.

Content on your instance: the session metadata and transcripts your nodes report to the control plane. This lives on the instance provisioned for you alone. We do not use it for any purpose beyond running the service, and we do not use it to train any model.

3. Why we use it

  • to provision, run, and maintain your instance;
  • to process orders, payment, renewal, and invoicing;
  • to send service notices (renewal reminders, incident notices, security advisories);
  • to troubleshoot faults and keep the service secure;
  • to meet obligations imposed by law.

We do not use your information for purposes not stated here. Any marketing email is consented to separately and carries a one-click unsubscribe.

4. Third parties and where data goes

The following cause data to leave our systems. Most are optional HERO features that only engage once you explicitly configure them:

  • Alipay and WeChat Pay — the order number and amount necessary to take payment; we receive the transaction result back.
  • Cloud providers — your instance runs on their hosts; DNS resolution and certificate issuance involve a DNS provider and a certificate authority.
  • Email provider — the recipient address and content needed to deliver service notices.
  • The optional LLM agent (--agent-mode llm) — if you enable it, main-chat state and transcript excerpts used for routing are sent to the model provider you configure. You choose and configure that provider.
  • The optional Telegram / Lark integrations — if you enable them, the relevant message content goes to that platform.
  • Optional Web Push — if you enable it, notifications are delivered via the browser vendor's push service.
  • An optional tunnel (Tailscale / Cloudflare Tunnel) — if you use one, traffic passes over that provider's network.

Apart from the above, what the law requires, and anything you separately consent to, we do not provide, sell, or trade your information to anyone.

5. Isolation and security

Each customer's hosted control plane is a separate instance with its own subdomain and its own data directory. The isolation boundary is the instance, not a tenant ID column in a shared database.

Measures we take include: HTTPS enforced in transit, password hashing and failure backoff on control-plane login, services running as dedicated non-root system accounts, daily backups, and access auditing.

We cannot promise absolute security. If a data-security incident occurs that may affect your interests, we will inform you promptly as the law requires, describing what happened, its likely impact, and what we have done.

6. Where data is stored, and for how long

Data is stored in cloud-provider facilities within the mainland of the People's Republic of China.

Account and transaction information is kept for the life of the service relationship and for as long as the law requires (accounting records for no less than 10 years).

Instance content is retained for 30 days after you terminate, then deleted. Logs are kept for 6 months.

7. Your rights

You have the right to access, copy, correct, and supplement your personal information, to withdraw consent, to request deletion, and to ask us to explain this policy.

To exercise any of these, write to the contact address published in the footer. We will respond within 15 working days of receiving your request, and will explain our reasoning if we decline.

8. Cookies

This site uses only the cookies needed to keep you signed in and to remember your language preference. There are no third-party advertising or cross-site tracking cookies.

9. Minors

The service is for businesses and developers and is not directed at children under 14. If we find we have collected a child's personal information without guardian consent, we will delete it promptly.

10. Updates

We will give at least 30 days' notice by email or in-product notice before any material change takes effect, and will update the effective date on this page.